Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Virus scan for WWI documents, SAP security note 1492505

SAP Note 1492505

SAP security note 1492505, "Virus scan for WWI documents". Below are the symptom and SAP recommended solution.

ComponentProduct Safety

Description

Symptom

In Environment, Health, and Safety (EHS), you can process or generate different file formats using Windows Wordprocessor Integration (WWI). As a result, virus-infected documents could enter the system or the front end, potentially leading to security breaches and undesired system behavior.

Solution

To address the issue of unscanned documents being uploaded via WWI, the following steps should be taken:

  • Activate/Deactivate Virus Check: use the profile /CBUI/WWI_REPORT_GEN to (de)activate the virus check. This check is optional, but the profile must always be configured.
  • Configure the Virus Scan Interface (VSI): detailed configuration instructions are available in the SAP NetWeaver Security Guide. Navigate through Documentation for SAP NetWeaver, System Administration, Security Guide, “Virus Protection and SAP GUI Integrity Checks” under “Security Guides for SAP NetWeaver According to Usage Types” for the usage type “Application Server (AS)”, “Using the Virus Scan Interface” section.
  • ABAP-Specific Configuration: set up the virus search function for WWI or define an inactive profile /CBUI/WWI_REPORT_GEN to deactivate it. Refer to Note 786179 for detailed information on using the virus scan interface.

Workaround: install an up-to-date virus scanner on the WWI server to enhance security, regardless of this note.

Reason and prerequisites

The EH&S application currently does not provide a virus scanning function during report generation. This omission could allow malicious documents to infiltrate the system.

References

  • 1772637 – Virus scan for WWI documents
  • 1492914 – Missing virus scan during report import

Full note on SAP: SAP Support Launchpad note 1492505

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More